US11411726B2

Cryptographic key generation using multiple random sources

Summary by NHIP

Multi-source key generation

The method generates cryptographic keys unconstrained by hardware security module resources using a random number generator fed by natural phenomena. Distinctive elements include triggers based on key counts falling below thresholds and quantum photoelectric effects as entropy sources.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A computer implemented method of generating cryptographic keys for a hardware security module (HSM), the method including generating a plurality of cryptographic keys and storing the cryptographic keys for use by the HSM in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator, such that a rate of generation of the cryptographic keys unconstrained by the resources of the HSM, wherein the hardware random number generator operates based on a plurality of statistically random entropy data sources originating from natural phenomena so as to increase a degree of randomness of the numerical data.

US11411726B2, drawing sheet 1
Sheet 1 of 5

Term

12.6 yearsleft in the term

Expires 2 May 2039.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

7 claims: 3 independent, 4 dependent

  1. 1
    Broadest claimClaim Score 40, average(NHIP)A computer implemented method of generating cryptographic keys for a hardware security module (HSM), the method comprising:generating a plurality of cryptographic keys;and storing the generated plurality of cryptographic keys in a key store of the HSM for use in providing cryptography functions upon occurrence of a trigger selected from the group consisting of: a number of available keys in the HSM falling below a threshold number, a number of available keys in the HSM falling below a threshold proportion, and a rate of consumption of keys meeting a threshold rate, wherein the plurality of cryptographic keys are generated based on numerical data generated by a hardware random number generator, such that generation of the cryptographic keys is unconstrained by resources of the HSM, wherein the hardware random number generator operates based on a plurality of statistically random entropy data sources originating from natural phenomena so as to increase a degree of randomness of the numerical data.
  2. 6
    A computer system comprising:a processor and memory storing computer program code for generating cryptographic keys for a hardware security module (HSM) by: generating a plurality of cryptographic keys;and storing the generated plurality of cryptographic keys in a key store of the HSM for use in providing cryptography functions upon occurrence of a trigger selected from the group consisting of: a number of available keys in the HSM falling below a threshold number, a number of available keys in the HSM falling below a threshold proportion, and a rate of consumption of keys meeting a threshold rate, wherein the plurality of cryptographic keys are generated based on numerical data generated by a hardware random number generator, such that generation of the cryptographic keys is unconstrained by resources of the HSM, wherein the hardware random number generator operates based on a plurality of statistically random entropy data sources originating from natural phenomena so as to increase a degree of randomness of the numerical data.
  3. 7
    A non-transitory computer-readable storage medium storing a computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer system to generate cryptographic keys for a hardware security module (HSM) by:generating a plurality of cryptographic keys;and storing the generated plurality of cryptographic keys in a key store of the HSM for use in providing cryptography functions upon occurrence of a trigger selected from the group consisting of: a number of available keys in the HSM falling below a threshold number, a number of available keys in the HSM falling below a threshold proportion, and a rate of consumption of keys meeting a threshold rate, wherein the plurality of cryptographic keys are generated based on numerical data generated by a hardware random number generator, such that generation of the cryptographic keys is unconstrained by resources of the HSM, wherein the hardware random number generator operates based on a plurality of statistically random entropy data sources originating from natural phenomena so as to increase a degree of randomness of the numerical data.